Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 463700 - dev-python/pygobject-3.8.0 with -fstack-protector-all - stack smashing attack in function <unknown> - terminated
Summary: dev-python/pygobject-3.8.0 with -fstack-protector-all - stack smashing attack...
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] GNOME (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Linux Gnome Desktop Team
Depends on:
Blocks: gnome-3.8
  Show dependency tree
Reported: 2013-03-29 10:18 UTC by iGentoo
Modified: 2013-03-31 13:36 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---

caribou-0.4.8-build.log (caribou-0.4.8-build.log,24.82 KB, text/plain)
2013-03-29 10:18 UTC, iGentoo
pygobject-3.8.0-build.log (pygobject-3.8.0-build.log.tar.xz,15.11 KB, application/x-xz-compressed-tar)
2013-03-30 07:11 UTC, iGentoo

Note You need to log in before you can comment on or make changes to this bug.
Description iGentoo 2013-03-29 10:18:04 UTC
Created attachment 343610 [details]

1. emerge dev-python/pygobject-3.8.0 with SSP.
2. emerge app-accessibility/caribou

build log:

/usr/bin/python2.6 -B /var/tmp/portage/app-accessibility/caribou-0.4.8/work/caribou-0.4.8/tools/ \
	-d "caribou" \
	-o caribou.settings.CaribouSettings
*** stack smashing detected ***: python2.6 - terminated
python2.6: stack smashing attack in function <unknown> - terminated
Report to
make[2]: *** [] Killed
make[2]: Leaving directory `/var/tmp/portage/app-accessibility/caribou-0.4.8/work/caribou-0.4.8-python2_6/data'

Portage 2.2.0_alpha170 (hardened/linux/amd64/selinux, gcc-4.8.0, glibc-2.17, 3.8.4-pax.x86_64 x86_64)
                         System Settings
System uname: Linux-3.8.4-pax.x86_64-x86_64-Intel-R-_Core-TM-2_Quad_CPU_Q9300_@_2.50GHz-with-gentoo-2.2
KiB Mem:     6114284 total,    748268 free
KiB Swap:   10484724 total,  10409544 free
Timestamp of tree: Fri, 29 Mar 2013 09:15:01 +0000
ld GNU gold (GNU Binutils 2.23.2) 1.11
ccache version 3.1.9 [disabled]
app-shells/bash:          4.2_p45
dev-java/java-config:     2.1.12-r1
dev-lang/python:          2.5.4-r5, 2.6.8-r1, 2.7.3-r3, 3.1.5-r1, 3.2.3-r2, 3.3.0-r1
dev-util/ccache:          3.1.9
dev-util/pkgconfig:       0.28
sys-apps/baselayout:      2.2
sys-apps/openrc:          0.11.8
sys-apps/sandbox:         2.6-r1
sys-devel/autoconf:       2.13, 2.69
sys-devel/automake:       1.12.6, 1.13.1
sys-devel/binutils:       2.23.2
sys-devel/gcc:            4.6.3, 4.7.2-r1, 4.8.0::hardened-dev
sys-devel/gcc-config:     1.8
sys-devel/libtool:        2.4.2
sys-devel/make:           3.82-r4
sys-kernel/linux-headers: 3.8 (virtual/os-headers)
sys-libs/glibc:           2.17
Repositories: gentoo systemd hardened-dev gnome custom
Installed sets: @local
ACCEPT_KEYWORDS="amd64 x86 ~amd64 ~x86"
CFLAGS="-Wall -Wextra -ggdb -march=native -pipe -O3 -fno-tree-vectorize -frecord-gcc-switches"
CONFIG_PROTECT="/etc /usr/share/config /usr/share/gnupg/qualified.txt /usr/share/polkit-1/actions /var/bind"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/splash /etc/terminfo"
CXXFLAGS="-Wall -Wextra -ggdb -march=native -pipe -O3 -fno-tree-vectorize -frecord-gcc-switches"
FCFLAGS="-Wall -Wextra -ggdb -march=native -pipe -O3 -fno-tree-vectorize -frecord-gcc-switches"
FEATURES="assume-digests binpkg-logs buildpkg collision-protect config-protect-if-modified distlocks ebuild-locks fixlafiles merge-sync multilib-strict news parallel-fetch preserve-libs protect-owned sandbox selinux sesandbox sfperms split-elog split-log splitdebug strict test test-fail-continue unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync webrsync-gpg xattr"
FFLAGS="-Wall -Wextra -ggdb -march=native -pipe -O3 -fno-tree-vectorize -frecord-gcc-switches"
LDFLAGS="-Wl,-O1 -Wl,--as-needed -Wl,--hash-style=gnu -Wl,--icf=safe"
MAKEOPTS="V=1 -j10"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTDIR_OVERLAY="/var/lib/layman/systemd /var/lib/layman/hardened-development /var/lib/layman/gnome /usr/local/portage"
USE="X acl alsa amd64 audit bash-completion berkdb bzip2 c++0x cairo caps cli cracklib crypt custom-cflags cxx dbus dri ffmpeg gdbm gmp gnome gpm gtk gtk3 hardened iconv icu ipv6 jit jpeg jpeg2k justify lzma mmx modules mudflap multilib ncurses nls nptl open_perms opengl openmp orc pam pax_kernel pcre png pulseaudio qt4 readline selinux session sse sse2 ssl svg systemd tcpd threads tiff udev unicode urandom vim-syntax xattr xinetd zlib" ABI_X86="x32 32 64" ALSA_CARDS="hda-intel" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" DRACUT_MODULES="bootchart btrfs caps dmsquash-live gensplash livenet lvm nfs ssh-client syslog systemd" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" INPUT_DEVICES="evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="en en_US zh zh_CN" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-3" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="pypy1_9 pypy2_0 python3_1 python3_2 python3_3 python2_5 python2_6 python2_7" QEMU_SOFTMMU_TARGETS="x86_64 arm mips64el ppc64" RUBY_TARGETS="ruby18 ruby19" USERLAND="GNU" VIDEO_CARDS="nouveau nvidia" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
USE_PYTHON="2.7-pypy-1.9 2.7-pypy-2.0 3.1 3.2 3.3 2.5 2.6 2.7"

                        Package Settings

dev-python/pygobject-3.8.0 was built with the following:
USE="cairo test threads -examples" PYTHON_TARGETS="python2_6 python2_7 python3_1 python3_2 python3_3"

app-accessibility/caribou-0.4.8 was built with the following:
USE="" PYTHON_TARGETS="python2_6 python2_7"
Comment 1 Pacho Ramos gentoo-dev 2013-03-29 11:32:21 UTC
Does it merge with python-2.7?
Does it merge without SSP?
Comment 2 iGentoo 2013-03-29 11:43:21 UTC
(In reply to comment #1)
> Does it merge with python-2.7?
> Does it merge without SSP?

Both python-2.6(In reply to comment #1)
> Does it merge with python-2.7?

/usr/bin/python2.7 -B /var/tmp/portage/app-accessibility/caribou-0.4.8/work/caribou-0.4.8/tools/ \
	-d "caribou" \
	-o caribou.settings.CaribouSettings
*** stack smashing detected ***: python2.7 - terminated
python2.7: stack smashing attack in function <unknown> - terminated
Report to
make[2]: *** [] Killed

> Does it merge without SSP?

I can merge app-accessibility/caribou, if building dev-python/pygobject-3.8.0 with -fno-stack-protector.
Comment 3 Pacho Ramos gentoo-dev 2013-03-29 11:48:56 UTC
Could you report this to upstream and post the link here?

Looks a problem with pygobject-3.8 :/
Comment 4 iGentoo 2013-03-30 07:11:12 UTC
Created attachment 343694 [details]
Comment 5 Pacho Ramos gentoo-dev 2013-03-31 13:36:59 UTC
+  31 Mar 2013; Pacho Ramos <>
+  +files/pygobject-3.8.0-stack-corruption.patch, pygobject-3.8.0.ebuild:
+  Fix stack corruption due to incorrect format for argument parser (#463700 by
+  Alphat-PC)